What I gathered is that this is just a way for malware to fetch additional instructions after already being executed through some unrelated process.
In other words, you've already been compromised, but the malignant code needs more instructions to continue effectively, so it fetches what appears to be an innocuous PNG file, which carries the instructions it needs.